esm
Audited by Socket on Mar 3, 2026
1 alert found:
MalwareThis file is a skill/README for a protein modeling SDK. It describes expected capabilities (generation, embeddings, structure prediction), legitimate install paths (pip), and use of a vendor Forge API requiring an API token. I found no code-level indicators of malware, backdoors, download-and-execute chains, or credential-harvesting behavior in the provided text. Main concerns are standard supply-chain risks from installing packages and fetching model weights, potential privacy/biosecurity sensitivity of uploading sequences/structures to a cloud service, a minor documentation inconsistency ('uv pip install') and use of a URL shortener. Overall the document appears functionally coherent with its stated purpose but requires normal operational caution when installing packages and when sending biological sequence/structure data to third-party cloud services.